SOC 2 Certification
Walnut EQ has completed an independent SOC 2 Type 1 audit and has scheduled its SOC 2 Type 2 audit — demonstrating our commitment to security, availability, and confidentiality from the earliest stages of the company.
An independent auditor has evaluated and confirmed that our security controls are suitably designed and implemented as of a specific point in time.
Controls assessed: Security · Availability · Confidentiality
Our Type 2 audit is scheduled and will verify that our security controls operate effectively over a continuous monitoring period — the highest standard for operational security.
Continuous monitoring period · Full operational audit
SOC 2 Trust Service Criteria covered:
What We Collect
Walnut EQ collects only what is necessary to deliver the service. We do not collect health records, clinical data, or any information that would make us a covered entity under HIPAA.
| Data Type | Purpose | Status |
|---|---|---|
| Employee name & phone number | Platform enrollment and SMS message delivery | Collected |
| Voluntary survey responses | General wellness and readiness signals; aggregated for employer dashboard | Collected |
| SMS engagement data | Message delivery confirmation, participation rates, streak tracking | Collected |
| Message timing preferences (Plus plan) | Delivering messages at employee's chosen time of day | Collected |
| Curriculum selections (Plus plan) | Personalizing content streams to employee's chosen topics | Collected |
| Company admin credentials | Platform access, employee enrollment management, dashboard access | Company-controlled |
What We Never Collect
This is arguably more important than what we do collect. Walnut EQ was deliberately architected to stay outside clinical data territory — which means there is an entire category of sensitive information we simply do not touch.
| Data Type | Why It Matters | Status |
|---|---|---|
| Medical or health records | Would require HIPAA compliance and BAA agreements | Never collected |
| Protected Health Information (PHI) | Would classify Walnut EQ as a HIPAA covered entity | Never collected |
| Clinical diagnoses or treatment data | Walnut EQ is not a clinical or healthcare provider | Never collected |
| Therapy session notes | We do not provide therapy or clinical mental health services | Never collected |
| Prescription or medication data | Outside scope of our educational platform | Never collected |
| Individual survey responses linked to named employees | Employer dashboards show aggregated, anonymized data only | Never in employer reports |
Who Controls Your Data
Walnut EQ is the platform host. Your organization is the data controller. This distinction is fundamental to how we operate.
Your company admin governs all employee data on the platform. This means your organization decides who is enrolled, what data is retained, and how platform settings are configured. Walnut EQ does not access, alter, or use your employee data for purposes outside of delivering the service as described in your Master Services Agreement.
Employee data belongs to the employer organization, not to Walnut EQ. Upon termination of your agreement, data handling will be conducted in accordance with the terms of your Master Services Agreement.
Walnut EQ is a push benefit. Employees are enrolled by their company admin and begin receiving messages automatically — no opt-in required, just like other employer-provided benefits. Employees may opt out at any time by replying STOP to any message. Opting out does not affect their employment or access to other benefits.
Survey response data is owned by Walnut EQ. Aggregated and anonymized survey responses collected through the platform are owned by Walnut EQ and used solely to generate the wellness and readiness insights surfaced in your employer dashboard. This data is always held in strict confidence — it is never sold, licensed, shared with third parties, or used for any purpose outside of delivering the service to your organization.
How We Protect Your Data
Our SOC 2 Type 1 certification confirms that the following controls are suitably designed and implemented. Our scheduled Type 2 audit will verify they operate effectively over time.
Administrative safeguards: Access to systems containing client data is restricted to authorized personnel only. Employees undergo security awareness training and are bound by confidentiality obligations. Background checks are conducted for personnel with data access.
Technical safeguards: Data is encrypted in transit and at rest. Access controls and authentication requirements limit who can access platform systems. Audit trails log access to sensitive data. Vulnerability management processes are in place.
Incident response: We maintain documented incident response procedures. In the event of a data breach affecting your organization, we will notify you promptly and provide details sufficient to support your own response obligations.
Infrastructure & Encryption
Walnut EQ is built on cloud infrastructure with encryption applied at every layer — in transit and at rest.
| Control | Implementation |
|---|---|
| Data in transit | All data transmitted between clients, employees, and Walnut EQ systems is encrypted using TLS 1.2 or higher |
| Data at rest | Stored data is encrypted using AES-256 or equivalent industry-standard encryption |
| Cloud infrastructure | Hosted on enterprise cloud infrastructure with SOC 2 certified data centers, physical access controls, and redundant availability zones |
| SMS delivery | Message delivery handled through contracted SMS subprocessors bound by confidentiality. Phone numbers and message content are used solely for delivery |
| Database access | Production databases are not directly accessible from the internet. Access requires authentication through secured internal networks |
| Backups | Data is backed up regularly. Backup integrity is tested periodically as part of our business continuity procedures |
Subprocessors
Walnut EQ uses a limited number of third-party subprocessors to deliver the service. All subprocessors are bound by confidentiality obligations and data protection requirements consistent with our own standards.
| Category | Purpose | Data Involved |
|---|---|---|
| Cloud infrastructure provider | Hosting, storage, and compute for the Walnut EQ platform | All platform data — encrypted at rest |
| SMS delivery provider | Routing and delivery of wellness messages to employee phone numbers | Phone numbers and message content for delivery only |
| Authentication provider | Secure login for company admin accounts | Admin email addresses and authentication credentials |
Vulnerability Management
We maintain an ongoing vulnerability management program to identify and remediate security risks before they can be exploited.
Security patching: Infrastructure and application components are patched on a regular schedule. Critical security patches are applied on an expedited basis.
Responsible disclosure: We welcome security researchers who identify potential vulnerabilities. Please report findings to support@walnuteq.com.
Access Control
Access to client data and production systems is strictly controlled on a least-privilege basis — employees only access what they need to perform their specific role.
Least-privilege access: Internal access to client data is limited to personnel with a documented business need. Access rights are reviewed regularly and revoked promptly upon role changes or departure.
Multi-factor authentication: MFA is required for all internal access to systems containing client data and for production infrastructure access.
Audit logging: Access to sensitive systems and client data is logged. Logs are retained and reviewed as part of our security monitoring program.
Employee security: All personnel with data access complete security awareness training. Employees are bound by confidentiality obligations as a condition of employment or engagement.
Offboarding: Access credentials are revoked within one business day of employee departure. System access is audited quarterly.
Incident Response & Business Continuity
We maintain documented procedures for responding to security incidents and service disruptions — so you know exactly what happens if something goes wrong.
Incident response plan: Walnut EQ maintains a documented incident response plan covering detection, containment, eradication, recovery, and post-incident review. The plan is reviewed and tested at least annually.
Breach notification: In the event of a security incident that affects your organization's data, we will notify you without undue delay and Notifications will include the nature of the incident, data categories affected, likely consequences, and remediation steps taken or planned.
Business continuity: Walnut EQ maintains business continuity procedures designed to ensure service availability during disruptions. Our infrastructure uses redundant availability zones to minimize downtime risk.
Data Sharing
Walnut EQ does not sell employee data. We do not share individual employee data with third parties for advertising, research, or commercial purposes.
| Recipient | What Is Shared | Status |
|---|---|---|
| Your company admin dashboard | Aggregated, anonymized wellness and readiness data — never individual named responses | Shared (anonymized) |
| SMS delivery providers | Phone numbers and message content for delivery only — bound by confidentiality | Subprocessor |
| Legal or regulatory authority | Only if required by applicable law, with notice to client where permitted | Legal obligation only |
| Advertising networks | — | Never |
| Third-party researchers | — | Never |
| Survey response data sold or licensed | Walnut EQ owns aggregated survey data but never sells, licenses, or shares it | Never sold or shared |
| Health insurers or health plans | — | Never |
Data Retention
Walnut EQ retains client data for the duration of the active agreement and as necessary to fulfill contractual, legal, and compliance obligations.
Upon termination of your Master Services Agreement, all Confidential Information — including employee data — will be destroyed or returned to your organization at your option, as described in your agreement.
Employee offboarding: When an individual employee is removed from the platform by your company admin, their data is removed from active systems in accordance with our data retention schedules.
Specific retention periods by data type are available upon request. Contact support@walnuteq.com.
Employee Rights
Individual employees enrolled in Walnut EQ have the following rights with respect to their data on the platform.
- 1 Right to opt out. Walnut EQ is a push benefit — employees are automatically enrolled when added by their company admin. Employees may opt out at any time by replying STOP to any Walnut EQ message. No action is needed to receive messages, and opting out has no effect on employment status or access to other company benefits.
- 2 Right to deletion. Employees may request deletion of their personal data by contacting their company admin. Requests will be honored in accordance with our data retention schedule and applicable law.
- 3 Anonymity in employer reporting. No individual employee's survey responses are ever surfaced to employer dashboards. All employer-facing data is aggregated and anonymized across the workforce.
- 5 Push benefit model. Walnut EQ is delivered as a push benefit — employees are enrolled by their company and receive messages automatically. No opt-in is required. Employees may opt out at any time by replying STOP.
Non-Clinical Statement
Walnut EQ does not process Protected Health Information (PHI) as defined under HIPAA. Because we do not provide clinical services or collect PHI, we are not a HIPAA covered entity and are not subject to HIPAA obligations. This is a deliberate design choice — not a gap in compliance.
If an employee is experiencing a mental health crisis or requires clinical care, they should contact a licensed healthcare provider, their primary care physician, or a crisis line such as the 988 Suicide & Crisis Lifeline (call or text 988).
Governing Law & Jurisdiction
This Privacy Policy and all data practices described herein are governed by and construed in accordance with the laws of the State of Delaware, without giving effect to principles of conflicts of law.
Walnut EQ's Master Services Agreement, which governs the relationship between Walnut EQ and client organizations, incorporates these privacy commitments by reference. In the event of any conflict between this policy and the terms of a signed MSA, the MSA controls.
Walnut EQ is incorporated in the State of Delaware and operates from 8 The Green, Dover, DE 19901, United States of America.
Contact & Privacy Requests
For privacy inquiries, data deletion requests, SOC 2 report requests, or security questionnaire responses, please contact us below.